Identity Threat Defense & Response (ITDR) - Proofpoint
Proofpoint ITDR enables proactive discovery and remediation of the identity risks used in ransomware and advanced persistent threats. The platform enables active management of the attack surface to remove the risk of privilege escalation and leverages deception technology to detect and respond to attacker lateral movement.
Features
- Discover identity risk across multiple steps in the attack chain
- Gain visibility across Active Directory, Entra AD, PAM, LAPS, Endpoints
- Automatically surface prioritised list of identity vulnerabilities exposed on Endpoints
- Manually or automatically remediate vulnerabilities such as Shadow Admins
Benefits
- Ensure early attacker detection and comprehensive threat investigations
- Agentless technology with low deployment/IT overhead
- Continuous and active defence through dynamic adjustment to IT/network changes
- Scales across networks of more than a million endpoints
Pricing
£5.89 a user a year
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
4 8 1 9 2 7 2 2 1 2 0 7 4 4 8
Contact
BROOKCOURT SOLUTIONS LIMITED
Phil Higgins
Telephone: 01737 886111
Email: contact@brookcourtsolutions.com
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Extends and enhances EDR solutions, integrates with PAM, SIEM, SOAR technologies.
- Cloud deployment model
- Hybrid cloud
- Service constraints
- The ITDR solution requires points of presence (connectors) into on premise environments in order to manage identity risks and deploy deceptions.
- System requirements
-
- Management Server - Windows 1 server required
- Identity Intelligence Server Linux On-prem only installations: 1 server required
- Hybrid and SaaS-only installations (ITD SaaS tenant): No server required
- Trap Server Windows Minimum 1 server required.
- Ransomware Server Windows Required for Ransomware Guard.
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
-
Dependant on Service Level Purchased
Support Portal - All Levels
Telephone Support Business Hours
Telephone Support 365x24x7 - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Self-Service, Platinum, Premium & Global
Self-Service: primary access via portal, phone support limited to business hours P1 issues, 2 authorised support contacts
Platinum: access via portal and phone, phone support for all priorities during business hours plus P1 issues 24x7, 4 authorised support contacts
Premium: access via portal and phone, phone support for all priorities during business hours plus P1 issues 24x7, 6 authorised support contacts, assigned Technical Account Manager
Global: available to Platinum and Premium only. phone access for all cases, all priorities 24x7x365, 12 authorised support contacts - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Implementation Services - Professional Services
Recurring Consultancy Services
Technical Account Management
Customer Success Management - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Not accessible from the service.
- End-of-contract process
- Services cease to function. Proofpoint support team will carry out full offboarding process.
Using the service
- Web browser interface
- Yes
- Supported browsers
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
The Proofpoint ITDR service interface provides continuous discovery and visibility of identity vulnerabilities in AD, Entra ID, AWS and endpoints. Lists vulnerabilities and prioritises the ones that need actioning first. These risks appear on a spectrum that ranges from non-critical to urgent. Enable automated remediation of identity vulnerabilities straight from the platform. Set up exception rules that are consistent with your security policies.
Provides visibility when attackers are active in your environment. With agentless deceptions, you can detect activity such as kerberoasting, password spraying,
privileged account abuse . automated forensic data collection to help guide response to active threats. - Accessibility standards
- None or don’t know
- Description of accessibility
- Management interface is accessible via web browser. No other access is required
- Accessibility testing
- N/A
- API
- Yes
- What users can and can't do using the API
- All core services are accessible via the API.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Findings and risks can be customised to align with the enterprise environment.
Scaling
- Independence of resources
- On premise the service can be installed on dedicated hardware. On SaaS the environment will be in a dedicated VPC.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Syslog of service usage is available.
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Proofpoint
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Up to Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
- TBCTBCTBC
- Data sanitisation process
- Yes
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation
- Deleted data can’t be directly accessed
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- Data can be exported from the system.
- Data export formats
- CSV
- Data import formats
- Other
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Policies, procedures, and standards comprising the Proofpoint information security program are reviewed and updated annually by the Proofpoint Global Information Security group and approved by the Proofpoint CFO.
Availability and resilience
- Guaranteed availability
- https://www.proofpoint.com/sites/default/files/legal-documents/pfpt-en-hosted-services-sla.pdf
- Approach to resilience
- https://www.proofpoint.com/sites/default/files/legal-documents/pfpt-en-hosted-services-sla.pdf
- Outage reporting
- https://www.proofpoint.com/sites/default/files/legal-documents/pfpt-en-hosted-services-sla.pdf
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Other
- Other user authentication
- Via proofpoint SSO
- Access restrictions in management interfaces and support channels
- For the management interface users will need to be authenticated via proofpoint SSO.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Other
- Description of management access authentication
- For the management interface users will need to be authenticated via proofpoint SSO.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- TBCTBCTBC
- ISO/IEC 27001 accreditation date
- 01/01/2024
- What the ISO/IEC 27001 doesn’t cover
- TBCTBCTBC
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber essentials plus
- No
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- The Proofpoint security program is led by the Proofpoint CSO. The program is based on identifying and mitigating risk to our personnel, the organization and the customer.
- Information security policies and processes
- Proofpoint's information security program is aligned with the requirements of NIST 800-53 and ISO 27001. However, we are not certified to the ISO 27001 standard.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Proofpoint has a documented change management policy that includes requirements around documented change tickets and review and approval by the Change Review Board.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Proofpoint performs internal and external vulnerability scanning and remediates applicable findings in line with the Proofpoint patch management policy.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Proofpoint has distributed monitoring in place for availability, performance, capacity and security. Alerts are directed to a 24x7 NOC or SOC for review, remediation and/or escalation.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Proofpoint has a documented Incident Response Plan that includes procedures to detect, investigate, remediate and communicate security incidents. A trained IRT team is responsible for the maintenance of the program.
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Covid-19 recovery
- Equal opportunity
- Wellbeing
Covid-19 recovery
As Proofpoint has grown, so have our programs continued to evolve to meet our colleagues’ needs, which we believe is essential to attract and retain employees of the highest caliber. We regularly and frequently communicate with and listen to our employees through small group surveys, interactive forums and townhalls, emails and online resources, to then iterate our processes and programs to improve the employee experience. For example, at our weekly townhall meetings, our CEO and other members of the executive team engage our global workforce with updates on the COVID-19 pandemic, our ongoing business operations, and other topics of interest.
Over the past year the employee experience has changed. They have encountered, observed and felt a transition from our traditional programs to virtual offerings that employees and their families can participate in, balancing a mix of live and on-demand activity. These online programs include educational classes taught by our fellow colleagues, mental health courses (mindfulness, resilience, meditation), cooking classes, financial well-being support, and “Vacation at Home” ideas. We realized that many of our parents sometimes need a little additional support, and because of this, Proofpoint created programming for Proofpoint kids, which included week-long STEAM camps during the summer, and offered ongoing story time, trivia games, art and dance, writing and oral presentation classes.
We launched in the summer of 2020, ProofpointEDU, a series of classes for Proofpoint kids taught by Proofpoint employees including topics like math, science, history, and cybersecurity for kids ages 5-15. Further, we introduced virtual team building programs such as trivia, bingo, escape rooms, and other group activities, all done via Zoom. Our Mindfulness program included music concerts, meditation, and resilience training.
In recognition of what we created for our employees, in July 2020, Proofpoint won the Espresa Innovation and Excellence Award for Culture Benefits.Equal opportunity
We embrace and foster the diversity of our team members, customers, stakeholders and consumers. Everyone is valued and appreciated for their unique backgrounds, experiences, thoughts and talents, all of which contributes to the growth and sustainability of our business. We strive to cultivate a culture and vision that supports and enhances the Company’s ability to recruit, develop and retain diverse talent at every level. As a global and distributed workforce, we recognize and celebrate our team members, their varied backgrounds and cultures. Our career development opportunities are designed to foster inclusivity through ongoing career conversations that actively advance and develop people of all backgrounds.
We believe that diversity, inclusion, and opportunity is a journey and we are committed to building a diverse and inclusive company and society for our employees, customers, partners, and shareholders. In order to create a more diverse and inclusive work environment, we provide education, training and tools so that all employees can become aware of bias, how it exists and how to mitigate it. As we continue to shape our work environment and world-class organization to be more inclusive and inviting, we are actively striving to build an extensive pipeline of talent through various programs. Our internal programs enable and empower our hiring managers to identify alternative and emerging talent pools and to create an inclusive candidate experience.Wellbeing
Together with our employees we are building a secure future, and it starts with securing our most important asset—our people. Our commitment to wellbeing is built on a foundation of helping employees get access to great programs and resources for maintaining their health. We offer global programs that provide and enhance a healthy, balanced lifestyle. Our localized benefits keep both the individual and family in mind, so our employees can take full advantage of what matters most to them, for where they are in life. We offer employer-paid life, disability and employee assistance programs. We also offer global programs for our employees’ physical, mental and financial health.
Since the COVID-19 pandemic was declared in early 2020 and our employees began working from home, we quickly transitioned to virtual offerings that employees and their families can participate in. These online programs include educational classes taught by our fellow colleagues, mental health courses (mindfulness, resilience, meditation), cooking classes, financial wellbeing support, and “Vacation at Home” ideas. Realizing that many of our parents sometimes need a little additional support, Proofpoint created a series for Proofpoint kids, which included week-long STEAM (Science, Technology, Engineering, Art and Math) camps during the summer, and offers ongoing story time, trivia games, art and dance classes. Also launched in the summer was ProofpointEDU, a series of classes for Proofpoint kids taught by Proofpoint employees including topics like math, science, history, and cybersecurity for kids ages 5-15. All of our programs are a balanced mix of live and on-demand activity.
Pricing
- Price
- £5.89 a user a year
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Full service offering as a Proof of Concept for 2 weeks as standard at customers request
- Link to free trial
- Requested with Brookcourt Solutions